LBI WatchDog - SECURITY_MANUAL

LBI WatchDog — Security Manual

Version: 1.1.1
Last Updated: September 2026
Published by: Light Bulb Ideas LLC
App: https://security.lbiwatchdog.com


Table of Contents

  1. Introduction
  2. Supported Panels
  3. Signing In
  4. System View (Arm / Disarm)
  5. Zones
  6. Snooze & Resume Alerts
  7. Users & Permissions
  8. WatchDog Settings (Integrators)
  9. ELK M1 Connection
  10. DSC PowerSeries Pro Connection
  11. Notifications
  12. LTE cellular (WatchDog WAN)
  13. Troubleshooting
  14. Support

1. Introduction

LBI Security is the customer-facing app for alarm panels connected through a LBI WatchDog. It is separate from lighting control.

Who Where to sign in
Home / site users (arm, disarm, zones) https://security.lbiwatchdog.com
Integrators (wire the panel, name zones, notify rules) https://lbiwatchdog.com → device → Settings → Security System
Super Admins Both apps; SA Diagnostics still shows agent health

WatchDog does not replace the panel keypad, monitoring station, or ElkRP / DLS programming software. It reads zone and arm state from the panel and sends arm/disarm/bypass commands using a user code entered at command time. Codes are not stored in the cloud unless the person checks Remember my code on this device (stored only in that browser).

If Security is not enabled on a WatchDog, the app shows: Security is not active on this system. Contact your system integrator or dealer to enable it.


2. Supported Panels

Vendor Connection options WatchDog modules
ELK M1 Gold RS-232 Port 0 (USB–RS232) or Ethernet via M1XEP (TCP 2101 / SSL 2601) elk_bridge.py
DSC PowerSeries Pro TL280 ITv2 over IP (ports 3072 / 3073) or TL280LE(R) RS-232 dsc_bridge.py

Agent 6.34.0+ required for the Security Bridge. 6.37.7+ for Prepare WatchDog (install libraries and scan USB serial from Settings — no SSH).

Field wiring for ELK is in the ELK Install Manual (including cellular-only / EXVIST LTE). 12 V / RV extras: ELK_M1_WATCHDOG_INSTALL.md. This Security manual covers day-to-day app use plus Settings configuration.


3. Signing In

  1. Open https://security.lbiwatchdog.com (phone or desktop).
  2. Use the same email/password as WatchDog, or a Security Only / Security Admin account created for this app.
  3. Optionally Stay logged in on this device.
  4. Pick a Site if more than one panel is linked to your account.

Security Only and Security Admin accounts cannot sign in to the lighting dashboard. Lighting users (company admin, manager, standard user) can use the Security app when the site has a bridge enabled.

Add to the phone home screen from the browser (PWA) for one-tap access.


4. System View (Arm / Disarm)

The System page shows arm state with a color emblem:

State Meaning
Disarmed Panel is off
Away Armed away (or vacation)
Stay Armed stay / night
Armed Armed (other armed mode)
Offline Bridge disabled, WatchDog offline, or panel not connected
Unknown Bridge has not reported a state yet

Buttons (shown only if your account is allowed):

Enter your panel user code (4 or 6 digits as programmed on the panel) before tapping a button. Check Remember my code on this device only on a private phone.

The code is sent to WatchDog and then to the panel. Invalid or restricted codes fail at the panel; the app shows the bridge error.

Refresh reloads the selected site. The bridge banner reports connected / listening / last error.

If your account is view-only: Your account can view status only. Contact your administrator for arm/disarm access.


5. Zones

Open Zones in the sidebar. Each row shows:

Bypass changes are sent to the panel immediately. Integrators also set per-zone bypass and auto-bypass in WatchDog Settings; those rules apply when arming with open zones.

Zone names are configured in WatchDog Settings → Security System, not in the Security app.


6. Snooze & Resume Alerts

Email and SMS alerts for a zone can include one-tap snooze links: 30 minutes, 24 hours, or 1 week. After tapping a link, a confirmation page is shown.

To turn notifications back on before the timer ends:

Snooze only pauses WatchDog notifications for that zone. It does not disarm the panel or bypass the zone.


7. Users & Permissions

7.1 Lighting vs Security roles

Role Lighting dashboard Security app
Super Admin / Company Admin Full Full (including Users)
Manager / Standard User Per tab permissions Full panel access unless a Security profile is set on the user
Security Only Blocked Arm/disarm (no bypass by default); email alerts
Security Admin Blocked Arm/disarm/bypass; manage Security users; email + SMS

7.2 Panel permission profiles (Security users)

Set in the Security app Users tab (Security Admin / company admin / super admin):

Profile Arm Disarm Bypass
Arm / Disarm / Bypass Yes Yes Yes
Arm / Bypass Yes No Yes
Disarm No Yes No

7.3 Adding a Security-only user

You can add the user in either app:

Security app: Users → + Add User
WatchDog: Users → Add User, role Security Only or Security Admin

  1. Email, name, role, password.
  2. Panel permissions: Arm / Disarm / Bypass · Arm / Bypass · Disarm.
  3. Alerts via: Email, Text (SMS), or Email and text (both). Enter alert email and/or E.164 phone (for example +15551234567).
  4. For SMS, check I confirm SMS consent has been obtained (STOP / HELP disclosure). Save is blocked without consent if SMS is enabled.
  5. Save User.

These users sign in at security.lbiwatchdog.com only. Lighting Notifications tab does not set Security recipients.

7.4 Panel keypad users (ELK)

On the same Users page, Panel Users lists keypad codes on the ELK or DSC panel. Add/edit/remove requires a master / current code at save time. Codes are sent to the panel and are never stored in the cloud. User 1 can be edited but not deleted.


8. WatchDog Settings (Integrators)

On lbiwatchdog.com (or beta) → select WatchDog → Settings → Security System:

  1. Check Enable Security Bridge.
  2. Click Prepare WatchDog (agent 6.37.7+). This installs elkm1-lib / pyserial, adds the agent user to dialout, and scans USB serial ports. No SSH required.
  3. Choose Panel vendor: ELK M1 Gold or DSC PowerSeries Pro.
  4. Fill connection fields (§9 or §10).
  5. For RV / security-only WatchDog units, leave Skip Shelly, GPIO, and relay telemetry checked.
  6. Configure Bypass & notifications:
  7. Zones table: number, name, Notify (Always / Armed only / Never), Bypass, Auto OK.
  8. Click Save Security Settings.

Bridge status should move to Connected (ELK) or Listening — awaiting TL280 then Connected (DSC IP). History records a config-change event.

Notify modes:

Mode When alerts send
Always Even if disarmed
Armed only Only while the partition is armed
Never No WatchDog email/SMS for that zone

Test connection (ELK) exercises the serial or M1XEP path from Settings.

Mobile control URL shown on the card: https://security.lbiwatchdog.com


9. ELK M1 Connection

9.1 RS-232 (Port 0)

M1 Gold Port 0 (female DB-9, DCE)
        │  straight-through RS-232
        ▼
USB–RS232 adapter (FTDI, true RS-232 levels — not 3.3 V TTL)
        │  USB
        ▼
LBI WatchDog
Setting Default
Serial device /dev/ttyUSB0 (from Prepare WatchDog scan)
Baud 115200 (must match Globals G34)
Format 8N1
Partition 1

Do not share Port 0 with an M1XEP / C1M1. Unplug the Ethernet expander when using USB serial.

Program on the M1 (ElkRP Globals G29–42 or keypad): G34 = 9 (115200); G35–G40 Transmit… ASCII = YES. G35 and G36 are the minimum for arm/zone status.

Users and zones are programmed on the panel (ElkRP or keypad). WatchDog names are labels for the app and notifications.

9.2 Ethernet (M1XEP)

  1. Unplug the USB–RS232 adapter.
  2. Plug M1XEP into Port 0 and Ethernet into the XEP.
  3. In Settings, Connection = Ethernet (M1XEP).
  4. Enter M1XEP IP, TCP port 2101 (non-secure) or 2601 with Use elks:// and the XEP password.

ElkRP Network mode can use the same XEP when the WatchDog bridge is disconnected.

Firmware 4.5.14 / 5.1.14 or newer is required if you feed DC into the AC terminals (RV / off-grid). See the ELK install guide.


10. DSC PowerSeries Pro Connection

10.1 ITv2 over IP (typical)

WatchDog listens; the TL280 connects inbound.

WatchDog field Typical value TL280 section
Listen host 0.0.0.0
Notification port 3072 [429]
Polling port 3073 [430]
Integration access code as programmed [423]
Partition 1

On the TL280: enable Ethernet integration [425]; set Integration Server IP [428] to the WatchDog’s LAN address.

Status Listening — awaiting TL280 is normal until the communicator connects.

10.2 RS-232 (TL280LE R-model)

Max cable 8 ft. Adapter TX→panel RX, RX→TX, GND→GND. Enable serial integration in [425]. Default baud 115200 [420]. Use Prepare WatchDog to find /dev/ttyUSB0.


11. Notifications

Security email/SMS are separate from lighting circuit alerts on the WatchDog Notifications tab.

History on the lighting dashboard still records security config changes and many panel events for integrators.


12. LTE cellular (WatchDog WAN)

When the site uses cellular for WatchDog, the standard modem is the EXVIST 4G LTE Dongle with EC25-AF Mini PCIe modem and SIM slot (Verizon / AT&T / T-Mobile / Rogers / U.S. Cellular / Telus).

LTE is cloud WAN only. The panel still talks to the WatchDog over RS-232 or Ethernet. Cell does not replace the keypad, monitoring-station radio, or ITv2/ASCII on the LAN.

Install with a security system:

  1. SIM in the EXVIST dongle, then the dongle in a WatchDog USB port.
  2. Keep the USB–RS232 adapter (ELK Port 0 / DSC serial) on a different USB port. Do not unplug serial to “free a port” for LTE if the panel still needs serial.
  3. Cellular-only (no customer internet): LTE Primary; plug panel/M1XEP into USB Ethernet (or eth0 only if WAN is LTE); enable Panel on WatchDog Ethernet. See ELK Install Manual §11 or DSC Install Manual §9.
  4. Settings → Connectivity & LTE: confirm Connected. Wrong-carrier APN is a Super Admin connectivity.apn change (Admin Manual §6.13).

ElkRP / DLS tunnels ride LTE when that is the WAN. ITv2 / ASCII never go over the radio to the panel vendor — only WatchDog cloud and the programming tunnel do.


13. Troubleshooting

Symptom What to try
“Security is not active” Integrator: enable Security Bridge and Save in WatchDog Settings
“No active security systems” User not assigned to the device; wrong company; bridge off
Offline / unknown arm state WatchDog online? USB seated? M1XEP IP pingable? DSC TL280 [428] pointing at WatchDog?
Prepare WatchDog timeout Agent 6.37.7+; device online; wait for command to complete
No serial ports listed Plug in FTDI adapter; click Prepare WatchDog again
ELK connected but no zones G35/G36 ASCII transmit; baud matches G34; correct partition
DSC stays Listening TL280 Ethernet integration; server IP = WatchDog; ports 3072/3073; access code [423]
Arm/disarm fails Valid panel user code for that partition; permission profile allows the action
No email/SMS Notify mode not Never; user Alerts via; snooze not active; SMS consent; E.164 phone
Cannot see Users tab Need Security Admin, company admin, or super admin
LTE up but panel Offline LTE is WAN only. Check USB serial vs EXVIST dongle (two different USB devices). Cellular-only: USB Ethernet + Panel on WatchDog Ethernet
Modem present — not connected SIM seated; wait 60s; wrong APN (Super Admin); role not Disabled

Do not use WatchDog GPIO UART pins or USB-TTL 3.3 V dongles for ELK Port 0.


14. Support

Light Bulb Ideas LLC
Phone: 617-618-LBI1
Email: info@lbiwatchdog.com
Security app: https://security.lbiwatchdog.com
WatchDog: https://lbiwatchdog.com

Integrator wiring: ELK Install Manual / DSC Install Manual. 12 V / RV: docs/ELK_M1_WATCHDOG_INSTALL.md


Document Revision History

Version Date Changes
1.1.1 September 2026 Public copy: call the on-site controller LBI WatchDog, not Pi.
1.1.0 September 2026 Users: WatchDog + Security app fields (Alerts via, consent, profiles). Notifications: lighting vs Security, Respond, browser push. EXVIST 4G LTE for WatchDog WAN on security jobs.
1.0.0 August 2026 Initial Security manual: app use, roles, snooze, ELK RS-232/M1XEP, DSC ITv2/RS-232, Settings Prepare WatchDog

© 2026 Light Bulb Ideas LLC. All rights reserved.

This manual is proprietary and confidential. Unauthorized distribution is prohibited.